package drone.basis.util ;

public class SqlUtil
{

	public final static String regex = "--|insert|delete|update|create|drop|truncate|alter|grant|execute|exec|call|declare|" ;

	// 只允许查询
	public static String filter (
			String param
	)
	{
		return param.replaceAll ( "(?i)" + regex , "" ) ; // (?i)不区分大小写替换
	}

}
